Privacy Policy

Read our privacy policy.


Placeholder. This page ships as a skeleton so the route, layout and footer link work out of the box. Replace every section below with a policy that matches what your deployment actually does, reviewed by a lawyer.

Last updated: [date]

1. What we collect

The starter stores: your name and email address, your hashed password or OAuth account link, your session records, your conversations and their messages, files you upload, and per-workspace usage counters. List anything else your build adds.

2. Why we collect it

Explain each purpose — operating your account, providing the AI features, enforcing plan limits, billing, and support.

3. Third parties

Name every processor your deployment uses and what reaches each one. In the default starter that is your database and file storage host, your model provider (prompts and attachments are sent to it to generate responses), Resend for transactional email, and Stripe for payments. Stripe receives payment details directly; the app never stores card numbers.

4. AI processing

Be specific: what is sent to the model provider, whether that provider trains on it under your agreement, and how long prompts are retained on their side.

5. Retention

State how long you keep conversations, uploads and usage records, and what deletion actually removes. The starter deletes a user's workspace data when the account is deleted from Settings.

6. Your rights

Describe how users access, export or delete their data, and how to contact you about it.

7. Cookies

Describe the cookies you set. The starter sets a session cookie for authentication and a theme preference.

8. Security

Describe your safeguards — encryption in transit, access controls, and how you handle incidents.

9. Changes

Explain how you notify users about changes to this policy.

10. Contact

[privacy@yourdomain.com]